Anthropic Confirms Infostealer Malware Drained Claude Tokens From $200-a-Month Subscribers
Updated
Updated · TechCrunch · Sep 8
Anthropic Confirms Infostealer Malware Drained Claude Tokens From $200-a-Month Subscribers
1 articles · Updated · TechCrunch · Sep 8
Summary
Anthropic told affected users a bad actor used infostealer malware to steal Claude login sessions, then consumed account usage through unauthorized access and minted Claude Code OAuth tokens.
One UK subscriber saw his Claude Max 20x usage jump from 45% to 55% during a period of no work; Anthropic suspended the account, invalidated sessions and refunded £44.49.
Reddit and GitHub posts suggest the issue hit multiple users, with reports of usage leaping from 0% to 49% in 12 minutes or max tokens burning for days without any activity.
Anthropic said it signs out affected users, revokes authorizations and issues refunds when it spots suspicious activity, but it declined to say how customers can independently identify misuse.
The case highlights a visibility gap in Claude billing and security: support tracks total usage, not itemized consumption, leaving some subscribers unable to tell what is draining tokens.